The images in this article were generated with artificial intelligence. How we publish
Two independent security teams described in July and August 2026 different ways in which Rovo - the integrated IA assistant in Atlassian products - can be induced to extract data to which an authenticated user already has access and send them to an external server controlled by an attacker. The found confirmed and closed by Atlassian involves a chain that was activated from a URL parameter (rovoChatPrompt); another, published by a different firm, describes an injection of hidden instructions within the content that Rovo processes and whose state of mediation was not publicly confirmed by the manufacturer at the time of the original communications..
Confirmed facts: Varonis Threat Labs reported that a URL parameter (rovoChatPrompt) could preload malicious instructions on Rovo Chat so that an authenticated user who click on a link will run those instructions with his privileges and the wizard exfilters data; that report was divulged through Bugcrowd, and Bugcrowd's record indicates that Atlassian deployed a server-side arrangement on 8 July 2026 and that the investigator validated the correction. On August 5, 2026, ProptArmor separately published a concept test in which a file uploaded with hidden instructions caused Rovo to search for internal content and open an external URL with these results, without explicit additional approval from the user. Link-based vector correction is confirmed; content-based chain status was described by its discoverer as unsolved when it was published. In addition, public searches in vulnerability databases indicated by the researchers themselves (e.g. NVD and the CISA catalogue) did not show identifiers or entries associated with these failures as at 8 August 2026 ( NVD, CISA KEV).

How the described chains work technically: Rovo works with the authenticated user's permissions and you can consult Jira, Confluence and external connectors according to the settings and authorized scope. In the variant detected by Varonis, a URL parameter preinjected a full prompt into the Rovo session; with a single click of an authenticated user, the wizard runs those instructions, collects user-accessible information (e.g. tickets or pages) and incorporates it into the path of an image or a request that Rovo gets - that request comes to the attacking server where it is registered. In the variant published by ProptArmor, the attacker inserted instructions into a user-loaded file; Rovo treated part of the file's content as directives and conducted internal searches and a request outgoing to a URL built with the results. In both cases, an elevation of privileges is not demonstrated: what comes out is what the authenticated user could already see, but without the user having consciously approved the exfiltration.
What this implies and who it affects: the main impact is exfiltration of data to which a legitimate user has access without that user having explicitly initiated the transfer. This is not a bypass of tenant-level permissions that allows you to see information outside the user's normal reach, but a new vector by which authorized data can leave the organization. In organizations where Rovo is enabled by default (documented by Atlassian for Standard, Premium and Enterprise plans) anyone with access to these functions could inadvertently activate one of these chains. The risk is higher in environments with wide connectors (SharePoint, Outlook, API keys in Confluence, etc.), where a single user can consult sensitive data.
What is confirmed and what is not: confirmed is that the URL parameter chain was reported, corrected by Atlassian and validated by the researcher; confirmed is also that ProptArmor published a concept test and stated that its method still worked with the option of "web search" deactivated in Rovo. It is not confirmed whether Atlassian applied additional changes after August 5 that mitigate the route described by ProptArmor; there is also no evidence of actual exploitation in the original public disclosures in customer environments. As of August 8, there were no public entries in NVD or the CISA catalogue associated with these chains.

Specific measures to be taken immediately by managers and users: 1) Review which apps and groups have enabled Rovo:: in organizations with administrative controls, limit Rovo to strictly necessary groups and disable it in apps that do not require assisted intelligence. 2) Not only to rely on the "web search" toggle: ProptArmor showed that Rovo can compose and recover URLs differently; treat that toggle as a layer, not a complete barrier. 3) Restringing and auditioning connectors: reduce the range of connectors (SharePoint, Outlook, others) and apply the principle of minor privilege in credentials and API keys. 4) Monitor output axes and proxy records: enable detailed HTTP / HTTPS output logging, review outgoing requests generated by attendees and look for fitch patterns to unexpected external domains. 5) Implement egress and DLP controls to block or alert when content with sensitive data is sent out of allowed domains. (6) Rotate evidence-exposed credentials and review audit of recent accesses if exposure is suspected. 7) Consult the mitigation status with Atlassian and maintain up-to-date systems; ask for clarification as to whether additional fixes were applied to the URLs recovery behavior made up of the agent.
Additional technical recommendations for security equipment: disable the automatic renderization of remote images in content generated by the IA where possible (this reduces an URLs exfiltration channel of images in Markdown), force validation of external domains by a white list, and practice internal rebound-team tests aimed at injections of prompt adjacent to raised content. For developers and identity managers, monitor session attributes and block actions involving fitch of external resources from sessions with elevated scopes without explicit approval.
In short: a vulnerability based on URL parameter was confirmed and corrected by Atlassian; a second, injection technique within content that the assistant processes, was publicly disseminated and its mediation was not documented in the original communications. The actual exposure is the output of data that the user can already see, not an escalation of privileges by default, but that does not reduce the urgency: in environments where IA attendees are integrated with multiple internal sources, a single user's ability to filter silent or unnoticed information can be significant. Organizations should act on configuration, permissions, registration and discharge to mitigate risk while awaiting clarification and final patches from the supplier.
Related
More news on the same subject.

GitLab critical alert: emergency patch fixes CVE-2026-19478 allowing to modify or eliminate public projects without credentials
GitLab published an emergency patch on August 17, 2026 to correct critical vulnerability in its self-hosted software (Community and Enterprise Edition) which, under certain cond...

When the MCP server keeps your credentials: the silent attack vector of the IA in production
The incorporation of IA agents into business processes has opened a practical way for production systems and data to be accessible from models: it is called Model Context Protoc...

Critical alert: CVE-2026-58231 in SAP Commerce Cloud could allow remote code execution; patch and urgent mitigation
A critical vulnerability that affects SAP Commerce Cloud, registered as CVE-2026-58231 and with maximum score 10.0 on the CVSS scale, it is being exploited attempts shortly afte...

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

HoneyMyte updates CoolClient with a signed kernel driver to hide processes and protect the C2 channel
Kaspersky has published an analysis that attributes to the actor known as HoneyMyte (also Mustang Panda) an updated version of the CoolClient backdoor that incorporates a signed...

GeoServer on zero-day vulnerability alert in jsonArrayContains with real risk of remote execution
The GeoServer open source project has a zero-day vulnerability that is being actively explored by attackers, according to researchers' public alerts and the watchTowr intelligen...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...